Junglewise Threat Intelligence

CVE-2026-49774: Filipe Nasc RD Station code injection in WordPress plugin

CVE-2026-49774 · Severity: critical · CVSS 9.9 · Published 2026-06-16

Executive brief

A vulnerability in the RD Station plugin for WordPress allows attackers to execute unauthorized code on the website's server. This plugin is used to integrate WordPress sites with the RD Station marketing platform. If exploited, an attacker could gain full control over the website, leading to data theft, site defacement, or the installation of backdoors.

Technical details

The RD Station plugin (integracao-rd-station) for WordPress contains a code injection vulnerability (CWE-94) that leads to Remote Code Execution (RCE). The flaw exists in versions up to and including 5.6.0. An attacker with 'Contributor' level privileges or higher can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary commands on the underlying server, potentially leading to a complete system compromise. The issue is resolved in version 5.7.0.

Affected products

  • Filipe Nasc RD Station (Integracao RD Station) <= 5.6.0

Timeline

  • 2026-05-12: disclosed: Reported by ParkHyunWoo
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-16: advisory: NVD entry published
  • 2026-06-04: patched: Version 5.7.0 released

References